WP Hotel Booking <= 2.0.9.2 - Improper Authorization on Multiple REST API Routes

2024-02-03 00:00
Anonymous

Strategic Overview

Status
Patched in 2.0.9.3
Affected PluginWP Hotel Booking
Affected Version<= 2.0.9.2
CVSS6.5Medium
CVEN/A
View all WP Hotel Booking vulnerabilities

Vulnerability Overview

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to an improper capability check on the 'pricing_plans', 'block_date', 'manager_bookings', and 'update_field_room' functions for the 'pricing-plans', 'block-date', 'manager-bookings', and 'update-field' REST routes, respectively, in versions up to, and including, 2.0.9.2. This makes it possible for unauthenticated attackers to expose sensitive information about bookings or modify them.

Technical Analysis

REMEDIATION: Update to version 2.0.9.3, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C